pp-printing-press-rich

Warn

Audited by Socket on Jul 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with a read-only CLI wrapper, but it relies on an external installer chain, adds MCP transitive trust, and exposes arbitrary webhook/feedback network sinks. No strong evidence of hidden credential theft or malware, but the install and data-routing footprint is broader than a minimal read-only inspection skill.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Jul 2, 2026, 04:53 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fcli-printing-press%2Fpp-printing-press-rich%2F@62d09be96423d7b90f9f0760537cdfea00805202883f5e6f6365d1410e51f54c
Security Audit — socket — pp-printing-press-rich